We've Kept Up With Technology. Have We Kept Track of the Dependency?
What a decision made elsewhere reveals about the infrastructure we're already standing on
By Louize Clark
On Monday, a US Defense Department official told the BBC that the Pentagon has stopped using Anthropic's AI tools. It follows a decision in February to designate the company a supply chain risk, after a dispute over the terms on which its models could be used, and a phase-out that was meant to be complete by late August.
I'm not going to relitigate that dispute here. Governments make security decisions, and they are entitled to. Whatever you think of this one, the principle that a state can decide which technology it will and won't run is not controversial.
What caught my attention was a smaller detail. According to people who spoke to the BBC, Claude was still in use in recent weeks, well past the deadline. It had been built into a larger platform the Pentagon relies on to organise intelligence. One person quoted in the report put it simply: these things are not plug and play. That, to me, is the real story.
Sit with that for a moment. This is the US Department of Defense. An organisation with a budget most countries would envy, a clear instruction from the top, a fixed deadline and alternative suppliers already under contract. And it still ran beyond its own announced deadline to take one AI model out of its systems.
So what would the same task look like for a business of fifty people? A practice of twelve? A charity running on three part-time staff and a handful of subscriptions?
I want to be careful here. The decision concerns US defence use. It doesn't change how Claude is available to businesses in the UK, and Anthropic said in February that commercial access was unaffected. This is not a story about one supplier. But it is a very clear picture of something I've been circling all year: an organisation can make a reasonable choice, build its work around it, and then find the conditions of that choice changed by someone else, for reasons it had no part in.
If that happened to you, how long would it take to unpick?
Six years without a pause
I've written before about the last six years, and I keep coming back to them because I don't think we've properly reckoned with them yet.
In 2020, the pandemic moved work, school, shopping, banking, GP appointments and family life onto screens in a matter of weeks. People who had never owned a smartphone learned video calls because it was the only way to see their grandchildren. Businesses that had never considered remote working rebuilt themselves around it by the following Monday.
We didn't get a moment to settle afterwards. A cost-of-living crisis. An energy crisis. War in Europe, and now conflict in the Middle East. Political upheaval at home. A steady erosion of trust in institutions we'd assumed would hold. And then, in the middle of all of it, generative AI, arriving into a workforce that was tired, stretched and grateful for anything that made the day a little lighter.
Jobs have gone. New ones have appeared, some of them roles that exist only to manage, supervise or work alongside AI. The way we draft, research, decide and communicate has changed in a handful of years.
Each of those changes, on its own, we adapted to. That's what people do, and we are remarkably good at it. But adapting and choosing are not the same thing. And I'm not sure we've had the space to stop and ask what all that adapting has quietly made us depend on.
The bottleneck
If you've ever run a marathon, or stood at the start of one, you'll know the feeling.
At the start line, you have a plan. You know your pace. You've trained for it. Then the field begins to move, and at some point the course narrows: a bridge, a sharp turn, a road that halves in width. Thousands of people try to fit through the same gap at once. For a while, you aren't really running your own race. You're moving at the speed of the people around you. You can't stop without being knocked. You can't step aside. You're carried.
That, I think, is where a great many organisations are with technology right now.
Nobody chose to be carried. A supplier switched on a new AI feature in a routine update. A competitor started turning quotes round in an hour. Customers began to expect an instant reply. A member of staff found a tool that saved them a morning a week, and a colleague followed. Every one of those adjustments made sense. Several of them were necessary just to stay in business.
But the momentum carrying us forward isn't always built on understanding. Much of it is built on everyone else moving. How many of the organisations setting the pace have actually worked out what they're doing? Some, certainly. Others are simply in front.
The speed of a bottleneck is rarely the real danger. The danger is that while you're being carried, you stop looking at the ground beneath you, and lose any clear sense of where you'd go if you needed to get out.
We've always depended on someone else
None of this is new, and I want to be fair about that. Organisations have always relied on technology they don't control. Email sits on someone else's servers. Payments run through someone else's network. Most of us have lived through the morning when Outlook goes down and the whole office discovers how much of its day ran through a single inbox. Productivity stops. People drift towards the kettle. Then it comes back, and we forget.
What has changed is not whether we depend. It's how deeply.
Picture an ordinary business that started using an AI assistant two years ago to help draft replies to customer enquiries. It worked well, so it was used for proposals too. Then for summarising meetings, preparing documents, triaging the inbox. The team got quicker. Turnaround that used to take three days became same day, and customers came to expect it. When someone left, they weren't replaced, because the work was still getting done. The person who knew how to do it all by hand moved on last spring.
Nobody in that business decided to become dependent. But if the tool disappeared tomorrow, they wouldn't simply lose a piece of software. They'd lose the capacity their staffing plan now assumes, the response times their customers now expect, and some of the know-how that used to live in a person.
Sometimes the dependency sits one step removed. A business might buy its booking system from one company, its customer service tool from another and its document software from a third, and feel reassured by the spread. If all three rely on the same underlying model, or the same cloud provider, for the part that matters, that spread offers far less protection than it appears to.
It's also worth being precise about what actually goes when access goes. Code written with the help of an AI tool doesn't stop working because the tool is withdrawn. A service that calls an AI model every time a customer uses it is a different matter entirely. And a team that has come to rely on AI to fix and adapt its own systems may find those systems keep running while its ability to change them quietly stalls. Those are three very different exposures. Could your business say which of them it has?
What is already holding you up
Before we ask how much further technology can take a business, we should understand what is already holding it up.
That isn't a theoretical exercise. The UK has a run of recent, very public examples of what happens when the systems underneath an organisation stop working, and I'd encourage anyone to read them less as cyber stories and more as dependency stories.
When Marks & Spencer was hit by a cyber attack in April 2025, it suspended online clothing and home orders for around seven weeks, and click and collect for the best part of four months. Shelves emptied as logistics systems were disrupted and staff fell back on manual processes. In May, the company estimated the hit to operating profit at around £300m. Rivals, meanwhile, gained market share while its website was down.
When Jaguar Land Rover was attacked that September, production across its UK factories stopped for five weeks. The Cyber Monitoring Centre later estimated the cost to the UK economy at around £1.9bn, which it described as the most economically damaging cyber event the UK has seen, and put the number of businesses affected at around 5,000. Most of those were never attacked themselves. They were suppliers, dealers and local firms whose own operations depended on JLR's.
Councils tell the same story at a different scale. In 2020, Redcar and Cleveland Borough Council lost its IT systems for more than three weeks, and staff fell back on pen and paper.
These were cyber attacks, rather than restrictions on access. Conflict adds another consideration: in March, the NCSC warned of heightened indirect cyber risk for organisations with a presence or supply chains in the Middle East. Different causes can still leave a business facing the same operational question: how long can it function without an essential system?
Now bring that down to size. Say you run a clinic, a salon or a small consultancy, and your online booking platform goes down. Can customers still reach you? Can your staff see today's appointments? Can you take payment, rearrange bookings, contact the people who are about to walk through the door? How many hours before it becomes lost income? How many days before it becomes a backlog you can't clear, or clients who have quietly booked with someone else?
Every function in a business has a tolerance: a point beyond which an interruption stops being an inconvenience and starts doing harm. For some functions it's a few hours. For others it's weeks. Have you worked out yours? If not, how would you know which dependencies matter most, how many people would be affected if one failed, or whether your fallback would hold for long enough to matter?
This is the commercial point I most want to make. A business that keeps building new services, new customer promises and new staffing assumptions on top of a dependency it has never examined is also increasing the number of people exposed when that dependency fails. Deep reserves may buy time. A business with thin margins and a few weeks of cash may have much less room to recover, and a prolonged interruption can be the end of it.
Sometimes the most valuable thing a business can do is pause long enough to understand what it's standing on, so that it builds in the right places.
Choice, in practice
This is where the conversation about sovereignty, national and organisational, becomes very practical.
Britain is investing heavily in sovereign AI, and rightly so. But sovereignty, for a country or a business, means more than owning the technology. It means being able to choose. If circumstances change, can you move without stopping?
Dependency isn't a yes or a no. Every organisation depends on something, and there's nothing wrong with that. The question is how much it would take to change direction, and whether you have that much. An alternative on the market doesn't help if you can't reach it within the time your business can tolerate being without. Moving might mean rebuilding integrations, retraining staff, checking outputs nobody has checked in months, keeping customers served through the transition, and recovering knowledge nobody has exercised in a year. If that costs more time, money and people than you have, then whatever the contract says, you aren't really choosing. You're dependent.
The Pentagon story is useful precisely because it isn't a small business story. It shows that even with authority, budget, a deadline and replacements lined up, unpicking something embedded still didn't happen on schedule. Most organisations have none of those advantages. And they won't get a six-month notice period if a supplier fails, a service is attacked, or a government, ours or anyone else's, decides a technology is no longer acceptable for a particular use.
I'm not predicting that last scenario. I raise it because the conditions under which we use technology are increasingly set by decisions about security, trade and permitted use, made a long way from our own offices. Those decisions may be entirely legitimate. The organisation relying on the technology still has to live with the consequences.
Finding your own pace again
Most of us are still in the crowd. The course hasn't opened up, and after the last six years I'm not sure we should wait for it to. But even in the thick of a race, you can lift your head, see where you are, and start working your way towards the edge, to the place where you get to set your own pace again.
We've kept up with the technology, often impressively, often under pressure we never asked for. What I'm less sure of is whether we've kept track of what all that keeping up has made us depend on.
That isn't a reason to slow down. It's a reason to look down. To know which parts of the business would stop if something went away, how many people that would affect, how long you could cope, and what you would actually do in the meantime.
So here is the question I'd leave you with.
If a decision made somewhere else meant you had to stop using a technology tomorrow, would you know what it would take to keep your business running?
AI Policies UK helps organisations see the AI infrastructure they're already standing on, chosen, inherited and embedded — before decisions like this one have to be made under pressure. Get in touch: louize@aipolicies.uk